Echo: k8s.io/kubernetes: security update to 1.3.0

low Tenable Self-Hosted Container Security Plugin ID 465544

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network
restrictions enforced by network policies during namespace deletion. The order in which objects are
deleted during namespace termination is not defined, and it is possible for network policies to be deleted
before the pods that they protect. This can lead to a brief period in which the pods are running, but
network policies that should apply to connections to and from the pods are not enforced. (CVE-2024-7598)

Solution

Update the k8s.io/kubernetes library and its related packages to version 1.3.0 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-7598

Plugin Details

Severity: Low

ID: 465544

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Low

Base Score: 1.8

Temporal Score: 1.3

Vector: CVSS2#AV:A/AC:H/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-7598

CVSS v3

Risk Factor: Low

Base Score: 3.1

Temporal Score: 2.7

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/22/2026

Vulnerability Publication Date: 3/20/2025

Reference Information

CVE: CVE-2024-7598